Description
In the Linux kernel, the following vulnerability has been resolved:

blk-iolatency: clear delay state when freeing policy data

io.latency can throttle a group which has no latency target of its own.
When a sibling misses its target, check_scale_change() scales down its
peers, and a peer that reaches queue depth one gets blkcg_use_delay()
called on it on every further scale-down, even with min_lat_nsec == 0.

iolatency_pd_offline() resets the target through
iolatency_set_min_lat_nsec(), which clears the delay only on a nonzero
to zero transition, so it never clears such a peer. Freeing the policy
data then leaves blkg->use_delay set and blkcg->congestion_count
elevated with nothing left that can drop it.

blk_cgroup_congested() then returns true for every task in that cgroup
and its descendants for as long as the cgroup lives: page_cache_sync_ra()
cuts readahead to a single page, page_cache_async_ra() skips it
altogether, and __folio_throttle_swaprate() takes swap_avail_lock and
schedules a throttle on anonymous folio allocation.

Clear the delay in iolatency_pd_free(). By then bio-held blkg
references have drained, or the queue is frozen for policy
deactivation, so check_scale_change() cannot re-arm it. The free
callback can also see policy data which was never attached to a blkg,
hence the pd->blkg check.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the blk‑iolatency subsystem incorrectly retains a delay flag when a latency policy is removed. The bug causes use_delay to stay set, making blkcg_congested() always return true for every task in the affected cgroup. This results in severe throttling of both read and write operations, producing a denial‑of‑service effect for workloads that rely on the cgroup. The flaw arises from improper state cleanup when freeing policy data and was fixed by ensuring the delay flag is cleared in iolatency_pd_free().

Affected Systems

The vulnerability affects all Linux kernel releases that include the blk‑iolatency implementation before the corrective patch. No vendor‑specific product or version ranges are supplied, so any system running an unpatched kernel that exposes blk‑iolatency groups is potentially impacted. The flaw manifests in block cgroups that have a target latency and subsequently enter and exit the policy data lifecycle.

Risk and Exploitability

The EPSS score is listed as less than 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the defect can be triggered by any local process that manipulates blk‑iolatency policies, the risk is primarily local to privileged users or kernel module authors. While the impact is confined to I/O‑bound workloads within the affected cgroup, prolonged throttling can degrade overall system performance.

Generated by OpenCVE AI on September 20, 2026 at 01:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the iolatency_pd_free fix.
  • If an immediate upgrade is not possible, avoid configuring blk‑iolatency policies or set min_lat_nsec to zero to prevent the delay flag from being set.
  • After applying a patch or configuration change, monitor system logs for blkcg_congested messages and verify that I/O throughput restores to normal levels.

Generated by OpenCVE AI on September 20, 2026 at 01:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-795

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: blk-iolatency: clear delay state when freeing policy data io.latency can throttle a group which has no latency target of its own. When a sibling misses its target, check_scale_change() scales down its peers, and a peer that reaches queue depth one gets blkcg_use_delay() called on it on every further scale-down, even with min_lat_nsec == 0. iolatency_pd_offline() resets the target through iolatency_set_min_lat_nsec(), which clears the delay only on a nonzero to zero transition, so it never clears such a peer. Freeing the policy data then leaves blkg->use_delay set and blkcg->congestion_count elevated with nothing left that can drop it. blk_cgroup_congested() then returns true for every task in that cgroup and its descendants for as long as the cgroup lives: page_cache_sync_ra() cuts readahead to a single page, page_cache_async_ra() skips it altogether, and __folio_throttle_swaprate() takes swap_avail_lock and schedules a throttle on anonymous folio allocation. Clear the delay in iolatency_pd_free(). By then bio-held blkg references have drained, or the queue is frozen for policy deactivation, so check_scale_change() cannot re-arm it. The free callback can also see policy data which was never attached to a blkg, hence the pd->blkg check.
Title blk-iolatency: clear delay state when freeing policy data
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:07.045Z

Reserved: 2026-09-11T19:38:34.791Z

Link: CVE-2026-90183

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:12.710

Modified: 2026-09-17T17:17:12.710

Link: CVE-2026-90183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses
  • CWE-795

    Only Filtering Special Elements at a Specified Location